
ChatGPT Billing Phish and Fake Snap Support Scams
This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted…
Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged Salesforce customer records and employee information.
Brinks Home has said it is investigating a cybersecurity incident after the group ShinyHunters claimed responsibility, stating the intrusion began with a Microsoft Entra vishing campaign. Rather than exploiting a software flaw, the described method relied on phone calls to employees, persuading them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps. If successful, these actions would grant attackers legitimate-looking access to corporate accounts, bypassing many technical controls entirely.
Brinks Home confirmed that the attacker threatened to publicly release data but has not confirmed what, if anything, was actually accessed. ShinyHunters has alleged theft of Salesforce customer records, employee PII, and large volumes of customer support chat logs, but these claims have not been independently verified.
Vishing campaigns targeting identity systems succeed because they exploit the human element rather than a technical vulnerability. Employees are conditioned to be helpful and responsive to IT-sounding requests, especially when a caller frames the situation as urgent, such as stopping suspicious activity or restoring account access. When an employee approves an authentication prompt or allows a new device to be registered, the resulting access looks legitimate to monitoring systems, making detection harder after the fact.
Defenders and employees should be alert to several warning signs:
These tactics target all employees, but help desk staff, IAM teams, and customer support are especially attractive targets because of the access and trust associated with their roles.
Organizations can reduce exposure to this style of attack by:
Because this technique targets identity rather than infrastructure, technical controls alone are not enough. Combining phishing-resistant MFA, tighter help desk verification, and ongoing monitoring gives organizations a better chance of catching these attempts before access is granted.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Brinks Home said it is investigating a cybersecurity incident after ShinyHunters claimed to have breached the company using a Microsoft Entra vishing campaign targeting employees.
According to the claims, attackers called employees and persuaded them to approve authentication requests, register attacker-controlled devices, or complete identity verification steps that granted access to corporate accounts.
ShinyHunters alleges theft of Salesforce customer records, employee PII, and customer support chat logs, though Brinks Home has not confirmed what data was accessed and these claims are not independently verified.
Recommended defenses include strengthening help desk identity verification, restricting unauthorized device registration and MFA enrollment, and monitoring Microsoft Entra and Salesforce for unusual authentication activity.
Brinks Home just got hit because employees answered one bad question: “Can you approve that Microsoft Entra prompt for me?” The caller says, “Hi, this is IT support. We’re seeing an authentication issue in Microsoft Entra, can you approve the verification prompt so we can secure your access?” That’s the whole play. According to ShinyHunters, this Microsoft Entra vishing trick let them get into Salesforce, employee data, even millions of support chats, without hacking software, just convincing people to tap Approve. If you ever get a surprise call about your account, and they want you to approve a prompt, your move is simple: hang up, and call your real IT number or open the official ticketing tool to verify first.

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk…

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting…